US2025274441A1PendingUtilityA1

Customer-managed identifier rotation and anonymous processing

Assignee: GOOGLE LLCPriority: Feb 22, 2024Filed: Feb 22, 2024Published: Aug 28, 2025
Est. expiryFeb 22, 2044(~17.6 yrs left)· nominal 20-yr term from priority
H04L 2209/42H04L 9/3218H04L 63/0421
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Example embodiments of the present disclosure provide for an example method including establishing a computing environment accessible to a second computing system. The computing environment can include an anonymous identifier management tool. A first anonymous identifier associated with the second computing system can be established. Message data is exchanged from the computing environment to a first computing system. The message data can be associated with the first anonymous identifier without revealing a non-anonymous identifier associated with the first computing system. The anonymous identifier management tool can periodically update the first anonymous identifier to a second anonymous identifier. The first anonymous identifier and mapping data associating the first anonymous identifier and the second anonymous identifier is deleted.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computing system comprising:
 one or more processors; and   one or more computer-readable media storing instructions that are executable to cause the one or more processors to perform operations, the operations comprising:
 establishing, by the computing system, a computing environment accessible by a second computing system, the computing environment comprising an anonymous identifier management tool; 
 establishing, by the anonymous identifier management tool, a first anonymous identifier associated with the second computing system; 
 exchanging message data from the computing environment to the computing system, wherein the message data is associated with the first anonymous identifier without revealing a non-anonymous identifier associated with the second computing system; 
 periodically updating, by the anonymous identifier management tool, the first anonymous identifier to a second anonymous identifier; and 
 deleting, by the anonymous identifier management tool, the first anonymous identifier and mapping data indicative of an association between the first anonymous identifier and the second anonymous identifier. 
   
     
     
         2 . The computing system of  claim 1 , wherein the computing system comprises a cloud service provider and the second computing system comprises a cloud service customer. 
     
     
         3 . The computing system of  claim 2 , the operations comprising:
 receiving, by the second computing system, a request to provide authentication in exchange for access to a cloud service;   providing, by the second computing system, a zero-knowledge proof code to prove the non-anonymous identifier associated with the second computing system;   receiving, by the second computing system, verification of authentication; and   updating, by the second computing system, the first anonymous identifier based on providing the zero-knowledge proof code to prove the non-anonymous identifier associated with the second computing system.   
     
     
         4 . The computing system of  claim 1 , the operations comprising:
 propagating, by the second computing system within the computing environment, the second anonymous identifier forward with instances associated with the first anonymous identifier; and   deleting, by the second computing system within the computing environment, the first anonymous identifier.   
     
     
         5 . The computing system of  claim 1 , wherein establishing, by the anonymous identifier management tool, the first anonymous identifier associated with the second computing system comprises:
 creating, on the second computing system, the first anonymous identifier, wherein the first anonymous identifier satisfies one or more rules defined by the computing system;   defining an authentication method for verifying the first anonymous identifier is associated with the non-anonymous identifier associated with the second computing system; and   storing by the second computing system, the first anonymous identifier and the authentication method, wherein the first anonymous identifier and the authentication method can later be used to verify the non-anonymous identifier of the second computing system to the computing system.   
     
     
         6 . The computing system of  claim 5 , wherein the authentication method comprises a zero-knowledge proof. 
     
     
         7 . The computing system of  claim 1 , wherein updating, by the anonymous identifier management tool, the first anonymous identifier associated with the second computing system is performed based on at least one of: (i) periodic requirement by the computing system to change the first anonymous identifier or (ii) in case of events where the second computing system reveals the non-anonymous identifier for a limited period of time until resolution. 
     
     
         8 . The computing system of  claim 1 , wherein the first anonymous identifier comprises at least one of: (i) alpha-numeric characters, (ii) logographs, (iii) images, or (iv) symbols. 
     
     
         9 . The computing system of  claim 1 , wherein establishing the first anonymous identifier associated with the second computing system comprises automatically generating the first anonymous identifier. 
     
     
         10 . A computer-implemented method, comprising:
 establishing, by a first computing system, a computing environment accessible by a second computing system, the computing environment comprising an anonymous identifier management tool;   establishing, by the anonymous identifier management tool, a first anonymous identifier associated with the second computing system;   exchanging message data from the computing environment to the first computing system, wherein the message data is associated with the first anonymous identifier without revealing a non-anonymous identifier associated with the first computing system;   periodically updating, by the anonymous identifier management tool, the first anonymous identifier to a second anonymous identifier; and   deleting, by the anonymous identifier management tool, the first anonymous identifier and mapping data indicative of an association between the first anonymous identifier and the second anonymous identifier.   
     
     
         11 . The computer-implemented method of  claim 10 , wherein the first computing system comprises a cloud service provider and the second computing system comprises a cloud service customer. 
     
     
         12 . The computer-implemented method of  claim 11 , comprising:
 receiving, by the second computing system, a request to provide authentication in exchange for access to a cloud service;   providing, by the second computing system, a zero-knowledge proof code to prove the non-anonymous identifier associated with the second computing system;   receiving, by the second computing system, verification of authentication; and   updating, by the second computing system, the first anonymous identifier responsive to providing the zero-knowledge proof code to prove the non-anonymous identifier associated with the second computing system.   
     
     
         13 . The computer-implemented method of  claim 10 , comprising:
 propagating, by the second computing system within the computing environment, the second anonymous identifier forward with instances associated with the first anonymous identifier; and   deleting, by the second computing system within the computing environment, the first anonymous identifier.   
     
     
         14 . The computer-implemented method of  claim 10 , wherein establishing, by the anonymous identifier management tool, the first anonymous identifier associated with the second computing system comprises:
 creating, on the second computing system, the first anonymous identifier, wherein the first anonymous identifier satisfies one or more rules defined by the first computing system;   defining an authentication method for verifying the first anonymous identifier is associated with the non-anonymous identifier associated with the second computing system; and   storing by the second computing system, the first anonymous identifier and the authentication method, wherein the first anonymous identifier and the authentication method can later be used to verify the non-anonymous identifier of the second computing system to the first computing system.   
     
     
         15 . The computer-implemented method of  claim 14 , wherein the authentication method comprises a zero-knowledge proof. 
     
     
         16 . The computer-implemented method of  claim 10 , wherein updating, by the anonymous identifier management tool, the first anonymous identifier associated with the second computing system is performed based on at least one of: (i) periodic requirement by the first computing system to change the first anonymous identifier or (ii) in case of events where the second computing system reveals the non-anonymous identifier for a limited period of time until resolution. 
     
     
         17 . The computer-implemented method of  claim 10 , wherein the first anonymous identifier comprises at least one of (i) alpha-numeric characters, (ii) logographs, (iii) images, or (iv) symbols. 
     
     
         18 . The computer-implemented method of  claim 10 , wherein establishing the first anonymous identifier associated with the second computing system comprises automatically generating the first anonymous identifier. 
     
     
         19 . One or more non-transitory computer-readable media storing instructions that are executable by one or more processors to perform operations comprising:
 establishing, by a first computing system, a computing environment accessible by a second computing system, the computing environment comprising an anonymous identifier management tool;   establishing, by the anonymous identifier management tool, a first anonymous identifier associated with the second computing system;   exchanging message data from the computing environment to the first computing system, wherein the message data is associated with the first anonymous identifier without revealing a non-anonymous identifier associated with the first computing system;   periodically updating, by the anonymous identifier management tool, the first anonymous identifier to a second anonymous identifier; and   deleting, by the anonymous identifier management tool, the first anonymous identifier and mapping data indicative of an association between the first anonymous identifier and the second anonymous identifier.   
     
     
         20 . The one or more non-transitory computer-readable media of  claim 19 , wherein the first computing system comprises a cloud service provider and the second computing system comprises a cloud service customer.

Join the waitlist — get patent alerts

Track US2025274441A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.